Cybersecurity - Information System Security Officer (isso)

Boeing Boeing · Aerospace · Berkeley, MO +2

This role is for a Cybersecurity Information System Security Officer (ISSO) at Boeing, focusing on maintaining and implementing security policies for classified computing domains. Responsibilities include performing security analysis, leading Assessment and Authorization (A&A) processes under RMF, overseeing configuration management, conducting risk assessments, and advising management on security best practices. Requires experience with RMF, cybersecurity policies, and security tools like NESSUS and ACAS.

What you'd actually do

  1. Perform security analysis of operational and development environments, threats, vulnerabilities and internal interfaces to define and assess compliance with accepted industry and government standards
  2. Lead and implement the Assessment and Authorization (A&A) processes under the Risk Management Framework (RMF) for new and existing information systems
  3. Facilitate development of Memorandums of Understanding (MOU), Interconnection Security Agreements (ISA), Risk Acknowledgement Letters (RAL) and support Continuous Monitoring (CONMON)
  4. Oversee configuration management of assigned systems; auditing systems to ensure security posture integrity
  5. Lead staff with assessments and test/analysis data to document state of compliance with security requirements

Skills

Required

  • IAM Level 1 DoD 8140.03 (previously 8570.01) compliant certification (i.e. , Security+ CE, CAP, CISSP, CASP, CISM, GSLC)
  • 3+ years of combined experience and/or education in cybersecurity, IT, or a related field
  • 3+ years of experience with the Risk Management Framework (RMF), cybersecurity policies, and RMF implementation (e.g., DAAG, CNSSI 1253, ICD-503, JSIG, or NIST SP 800 series)
  • 3+ years of experience utilizing security relevant tools, systems, and applications in support of Risk Management Framework (RMF) to include NESSUS, ACAS, DISA STIGs, SCAP, Audit Reduction, and HBSS

Nice to have

  • Active Top Secret Security Clearance
  • Currently hold certification in good standing to satisfy IAM Level III (CISSP, GSLC or CISM)
  • 3+ years of experience as an information system security officer (ISSO) or information system security manager (ISSM) supporting classified programs
  • 3+ years of experience assessing and documenting test or analysis data to show cyber security compliance

What the JD emphasized

  • Risk Management Framework (RMF)
  • cybersecurity policies
  • RMF implementation
  • security relevant tools, systems, and applications in support of Risk Management Framework (RMF)
  • classified programs